Cyber threat actor
Hafnium
PRC state-sponsored · active since 2017
Author of the 2021 ProxyLogon Microsoft Exchange zero-day campaign that compromised 30,000+ servers worldwide.
Aliases
Silk Typhoon
Primary targets
Defense contractors Higher education Law firms Think tanks Infectious disease researchers
MITRE ATT&CK techniques
3 techniques mapped · click any technique ID to open the MITRE ATT&CK entry, any CVE to view its NVD record, or any citation for source reporting.
| Tactic | Technique | Procedure | Targets | Citation |
|---|---|---|---|---|
| Initial Access | T1190 Exploit Public-Facing Application (ProxyLogon) | Mass-exploitation of the ProxyLogon Exchange Server zero-day chain before patches were available. | 30,000+ Exchange servers globally | Microsoft ProxyLogon |
| Persistence | T1505.003 Server Software Component: Web Shell (China Chopper) | Dropped China Chopper variant web shells on compromised Exchange servers for persistence. | - | Microsoft ProxyLogon |
| Collection | T1114.002 Remote Email Collection | Full mailbox exports of targeted users at defense, law, education, and infectious-disease research orgs. | - | Microsoft ProxyLogon |
Curated incidents
- 2021-03-02·Cross-sector·GlobalHafnium ProxyLogon zero-days compromise 30,000+ Exchange servers
Mass-exploitation of CVE-2021-26855 chain before patches were available.